Area to be audited
(business function, system, physical location etc.)
Identify audit purpose
Understand IT environment
Identify specific systems, function or units to be reviewed
Fieldwork and Documentation Phase
Develop audit program
Identify SOP for review
Identify regulatory compliance requirement
Identify individuals to interview
Develop audit tools and methodology
Identify criteria for evaluating the test
Define methodology to evaluate that test
Conduct risk assessment
Interview auditee to inquire about areas of concern